CVE-2005-4351
Summary
| CVE | CVE-2005-4351 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-12-31 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The securelevels implementation in FreeBSD 7.0 and earlier, OpenBSD up to 3.8, DragonFly up to 1.2, and Linux up to 2.6.15 allows root users to bypass immutable settings for files by mounting another filesystem that masks the immutable files while the system is running. |
Risk And Classification
Primary CVSS: v2.0 4.3 from [email protected]
AV:L/AC:L/Au:S/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Dragonfly | Dragonfly | All | All | All | All |
| Operating System | Freebsd | Freebsd | 7.0 | current | All | All |
| Operating System | Freebsd | Freebsd | All | stable | All | All |
| Operating System | Linux | Linux Kernel | All | All | All | All |
| Operating System | Openbsd | Openbsd | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.redteam-pentesting.de/advisories/rt-sa-2005-015.txt | af854a3a-2127-422b-91ae-364da2661108 | www.redteam-pentesting.de | Exploit, Vendor Advisory |
| [Full-disclosure] BSD Securelevels: Circumventing protection of files flagged immutable | af854a3a-2127-422b-91ae-364da2661108 | lists.grok.org.uk | Exploit, Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Neohapsis Archives - OpenBSD - #1523 - Rationale for allowing mount_mfs in securelevel 2? | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| RedTeam Pentesting GmbH - Page not found | af854a3a-2127-422b-91ae-364da2661108 | www.redteam-pentesting.de | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.